Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
ID: 9a054161-8885-5e06-8348-80d0ce59dbb0
STIX ID: report--9a054161-8885-5e06-8348-80d0ce59dbb0
Feed Name: The Hacker News
Microsoft and other vendors report an active phishing campaign since April 2026 targeting hotel and hospitality staff in Europe and Asia that leverages Calendly and Google redirects (authentication laundering) to deliver photo-themed ZIPs containing LNK files which execute PowerShell to drop a Node.js runtime and a JavaScript implant tracked as TonRAT; the implant resolves C2 via the TON blockchain and opens encrypted WebSocket channels. Observed techniques include Turnstile challenge anti-analysis, headless browser automation, forced shutdowns, and dual persistence paths; Microsoft has not confirmed data theft, ransomware, or named victims, and remediation must remove both RunOnce/ProgramData and Node.js-related Run keys and user-space runtime/files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
